Fetching from the wire…
Security2026-05-25 · source-backed
Researchers from Zhejiang University, NUS, and NTU presented at IEEE S&P demonstrating that imperceptible audio perturbations embedded in podcasts, music, or YouTube videos can trigger AI voice assistants to execute commands: unlocking doors, transferring funds, exfiltrating data. As voice agents gain tool-use capabilities, audio becomes a command surface you can't inspect. This is prompt injection through the microphone. 883-upvote r/singularity discussion.
Each link below shares sources, entities, or timing with this story.
These aren't theoretical. Security researchers disclosed 10 IPI payloads seen in the wild, built for financial fraud, data destruction, and API-key theft by poisoning web content agents crawl, summarize, or index for RAG. Related 2026 work finds attack success rates above 85%...
Researchers at University of Missouri-Kansas City disclosed Ghostcommit on July 11: malicious instructions embedded inside image files that AI coding agents read and execute during pull-request work (SecNews). It exploits a structural blind spot. Neither human nor AI reviewers...
Since early summer, Amazon order emails list item counts instead of naming items (The Verge). The reason is defensive: detailed receipts were feeding purchase history to assistants living in the inbox, notably Google's, turning a transactional email into a competitor's persona...
The Verge reports a new My Ad Center section disclosing whether an ad on Search, Discover, or YouTube used AI in creation or editing. It's viewer-level disclosure, not an advertiser restriction, and the definitional gap will matter enormously as generative tooling becomes the...
The first systematic study of deceptive UI impact on LLM web agents, accepted at IEEE S&P 2026, tested against real e-commerce, streaming, and news dark patterns. Gemini 2.5 Pro: 65.78% susceptibility. Claude 3.7 Sonnet: 53.79%. GPT-4o: 51.26%. Guardrail models and prompt post...
Researchers systematically measured what happens when adversarial instructions are embedded in project documentation that high-privilege agents are directed to read. The result: agents with terminal, filesystem, and network access blindly execute the instructions and exfiltrat...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.